File name: | XWorm V3.1.exe |
Full analysis: | https://app.any.run/tasks/a45fbd57-fa5d-43f6-86d6-13be0c697514 |
Verdict: | Malicious activity |
Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
Analysis date: | April 01, 2023, 09:44:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | C0897E921672C2619ACC5D9FF1329860 |
SHA1: | 683D5C1B0858CD5089E4A60BA344872531584D35 |
SHA256: | 607C8E5C6B50F2E6DDC15BAC7D48C57A81DB1B893FD5ECD8D112C73CD1DC5A52 |
SSDEEP: | 196608:FLQ6B/XKUDz9NoUXJzUWi7MYjBVvo5/UVC:ZFlaU/9NZXJZinjB9oxgC |
.exe | | | Win32 Executable Delphi generic (37.4) |
---|---|---|
.scr | | | Windows screen saver (34.5) |
.exe | | | Win32 Executable (generic) (11.9) |
.exe | | | Win16/32 Executable Delphi generic (5.4) |
.exe | | | Generic Win/DOS Executable (5.2) |
AssemblyVersion: | 0.0.0.0 |
---|---|
ProductVersion: | 0.0.0.0 |
OriginalFileName: | XHVNC.exe |
LegalCopyright: | |
InternalName: | XHVNC.exe |
FileVersion: | 0.0.0.0 |
FileDescription: | |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 0.0.0.0 |
FileVersionNumber: | 0.0.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x20cc |
UninitializedDataSize: | - |
InitializedDataSize: | 7552000 |
CodeSize: | 5120 |
LinkerVersion: | 2.25 |
PEType: | PE32 |
ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
TimeStamp: | 1992:06:19 22:22:17+00:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 19-Jun-1992 22:22:17 |
FileDescription: | - |
FileVersion: | 0.0.0.0 |
InternalName: | XHVNC.exe |
LegalCopyright: | - |
OriginalFilename: | XHVNC.exe |
ProductVersion: | 0.0.0.0 |
Assembly Version: | 0.0.0.0 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 8 |
Time date stamp: | 19-Jun-1992 22:22:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 0x00001000 | 0x000013B8 | 0x00001400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.34099 |
DATA | 0x00003000 | 0x0000007C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.11763 |
BSS | 0x00004000 | 0x00000695 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00005000 | 0x00000302 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.47732 |
.tls | 0x00006000 | 0x00000004 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x00007000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.199108 |
.reloc | 0x00008000 | 0x000001C8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 5.7833 |
.rsrc | 0x00009000 | 0x0073319C | 0x00733200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 7.80026 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.18006 | 572 | Latin 1 / Western European | UNKNOWN | RT_VERSION |
2 | 1.85555 | 67624 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 2.02984 | 16936 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 2.19153 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 2.39528 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 2.81402 | 1128 | Latin 1 / Western European | UNKNOWN | RT_ICON |
32512 | 2.79908 | 90 | Latin 1 / Western European | UNKNOWN | RT_GROUP_ICON |
A1 | 7.86357 | 7278080 | Latin 1 / Western European | UNKNOWN | RT_RCDATA |
A2 | 5.1498 | 162816 | Latin 1 / Western European | UNKNOWN | RT_RCDATA |
B1 | 3.52164 | 14 | Latin 1 / Western European | UNKNOWN | RT_RCDATA |
kernel32.dll |
shell32.dll |
shfolder.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2512 | "C:\Users\admin\AppData\Local\Temp\XWorm V3.1.exe" | C:\Users\admin\AppData\Local\Temp\XWorm V3.1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
3060 | "C:\Users\admin\AppData\Local\Temp\dark.exe" | C:\Users\admin\AppData\Local\Temp\dark.exe | XWorm V3.1.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Microsoft Jet Version: 12.2.1 Modules
RedLine(PID) Process(3060) dark.exe US (137) Search Reflection Ammo Function Info Roaming UNKNOWN cFileStreamredFileStreamit_cFileStreamardFileStreams FileStream \ ToString os_crypt encrypted_key Inner Unknown : Read Kill Microsoft GetDirectories MSObject12 EnumerateDirectories String.Replace String.Remove net.tcp:// / localhost cf407bc0c9a8384bb62aa110b7844cfe Authorization ns1 CSUHBigGMDMsBj5VIBMDVSE3Clw0AjgbPCRRRA== FCQqIDZdHQAwC05Y Falsely MSValue3 EnumerateFiles ExpandEnvironmentVariables MSValue2 MSValue1 FullName Replace Directory wa l et d a t . *wallet* _ T e gr am ex \TeEnvironmentlegraEnvironmentm DEnvironmentesktoEnvironmentp\tdEnvironmentata Environment \Discord\Local Storage\leveldb *.loSystem.Collections.Genericg System.Collections.Generic 1 String MyG string.Replace %USERPFile.WriteROFILE%\AppFile.WriteData\RoamiFile.Writeng File.Write Handler npvo* %USERPserviceInterface.ExtensionROFILE%\ApserviceInterface.ExtensionpData\LocaserviceInterface.Extensionl serviceInterface.Extension ProldCharotonVoldCharPN oldChar nSystem.CollectionspvoSystem.Collections* System.Collections EngSubs Microsoft\Windоws - AddRange % ( UNIQUE " FileStream.IO string.Empty uint UnmanagedType hKey pszProperty Encoding bMasterKey {0} | https://api.ip.sb/ip SELSystem.Windows.FormsECT * FRSystem.Windows.FormsOM WinSystem.Windows.Forms32_ProcSystem.Windows.Formsessor System.Windows.Forms roSystem.Linqot\CISystem.LinqMV2 System.Linq SELSystem.LinqECT * FRSystem.LinqOM WinSystem.Linq32_VideoCoSystem.Linqntroller AdapterRAM Name SOFTWARE\WOW6432Node\Clients\StartMenuInternet SOFTWARE\Clients\StartMenuInternet shell\open\command Unknown Version SELESystem.ManagementCT * FRSystem.ManagementOM WiSystem.Managementn32_DisSystem.ManagementkDrivSystem.Managemente System.Management SerialNumber SELSystem.Text.RegularExpressionsECT * FRSystem.Text.RegularExpressionsOM Win32_PSystem.Text.RegularExpressionsrocess WSystem.Text.RegularExpressionshere SessSystem.Text.RegularExpressionsionId=' System.Text.RegularExpressions ' FileSystem SSystem.ELECT * FRSystem.OM WiSystem.n32_ProcSystem.ess WherSystem.e SessiSystem.onId=' System. ExecutablePath [ ] Concat0 MConcatb oConcatr Concat0 Concat SELEMemoryCT * FMemoryROM WiMemoryn32_OperMemoryatingSMemoryystem Memory {0}{1}{2} x32 x64 x86 SOFTWARE\Microsoft\Windows NT\CurrentVersion ProductName CSDVersion _[ Network\ 80 81 0.0.0.0 Auth_valuecf407bc0c9a8384bb62aa110b7844cfe Err_msg BotnetDARKWEB C2 (1)89.22.234.180:40608 | |||||||||||||||
3712 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2512) XWorm V3.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2512) XWorm V3.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2512) XWorm V3.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2512) XWorm V3.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3712) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9ACE5C3C-EC4A-4592-9073-FCED8255A397}\{F0630729-F14B-440B-844A-CD32F17DD61E} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3712) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9ACE5C3C-EC4A-4592-9073-FCED8255A397} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3712) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{5599CD7D-85EA-4455-8155-5845C3E397BE} |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2512 | XWorm V3.1.exe | C:\Users\admin\AppData\Local\Temp\dark.exe | executable | |
MD5:0D1B1C61A083B253810EDE683435E6BC | SHA256:FB486189117A81DCCE0E772311FD220162E02214D37E6BDDE408790E18D10BDB |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3060 | dark.exe | 89.22.234.180:40608 | — | Hosting technology LTD | RU | malicious |
PID | Process | Class | Message |
---|---|---|---|
3060 | dark.exe | A Network Trojan was detected | ET MALWARE RedLine Stealer TCP CnC net.tcp Init |